top title background image
flash

HSBC ... Wire Transfer Copy.exe

Status: finished
Submission Time: 2021-11-25 18:48:24 +01:00
Malicious
Trojan
Evader
FormBook

Comments

Tags

  • exe
  • Formbook
  • HSBC

Details

  • Analysis ID:
    528773
  • API (Web) ID:
    896295
  • Analysis Started:
    2021-11-25 18:55:52 +01:00
  • Analysis Finished:
    2021-11-25 19:06:13 +01:00
  • MD5:
    99b154970d15748d1df9025f675ecc76
  • SHA1:
    75503611daf18643a401c2020ae9e045111b7f1f
  • SHA256:
    13af03cd2db9c68bc397fd81f101287df005f27bc806737ffad390324a068d4c
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
Score: 100
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

Third Party Analysis Engines

malicious
Score: 11/65
malicious
Score: 18/45

IPs

IP Country Detection
34.102.136.180
United States
172.217.168.83
United States

Domains

Name IP Detection
www.catproductreviews.com
0.0.0.0
www.piramsgprodiet.store
0.0.0.0
www.gramaltinrafineri.com
0.0.0.0
Click to see the 3 hidden entries
ghs.google.com
172.217.168.83
gramaltinrafineri.com
34.102.136.180
catproductreviews.com
34.102.136.180

URLs

Name Detection
www.atlantiscompania.com/m4n8/
http://www.gramaltinrafineri.com/m4n8/?5jblCF=6FC/YAdxArGDbOG0ZU8ranLB3olQ8/HIU17UMwKJ54PfoS0z6/xA4+VoDBKhLnDEQ6+k&l0G=-Zrd9J1pqHLdHPo
http://www.catproductreviews.com/m4n8/?l0G=-Zrd9J1pqHLdHPo&5jblCF=fqwcloTwW+H6Usea82LuZckhsM6vXxH+7LRp9WPFBQLwjEJmVheIZ7PCXY+dS9vifeb6
Click to see the 2 hidden entries
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
https://www.piramsgprodiet.store/m4n8/?l0G=-Zrd9J1pqHLdHPo&5jblCF=tUrd37IHNwUNrKy1BA5QR6EUYG6BNH

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\HSBC ... Wire Transfer Copy.exe.log
ASCII text, with CRLF line terminators
#